Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: 2020-0094 Moderate: systemd Denial Of Service Vulnerability

mageia
Calendar Grey February 21, 2020
Dist Mageia Esm H88
Recent Mageia systemd updates tackle critical security vulnerabilities linked to potential denial of service scenarios. Find out more specifics today.
Updated systemd packages fix security vulnerabilities: It was discovered that systemd incorrectly handled certain udevadm trigger commands

Summary

Updated systemd packages fix security vulnerabilities:
It was discovered that systemd incorrectly handled certain udevadm trigger commands. A local attacker could possibly use this issue to cause systemd to consume resources, leading to a denial of service (CVE-2019-20386).
Tavis Ormandy discovered that systemd incorrectly handled certain Polkit queries. A local attacker could use this issue to cause systemd to crash, resulting in a denial of service, or possibly execute arbitrary code and escalate privileges (CVE-2020-1712).

References

- https://bugs.mageia.org/show_bug.cgi?id=25964

- https://ubuntu.com/security/notices/USN-4269-1

- https://www.cve.org/CVERecord?id=CVE-2019-20386

- https://www.cve.org/CVERecord?id=CVE-2020-1712

Resolution

SRPMS

- 7/core/systemd-241-8.5.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 21 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0094.html
Type: security
CVE: CVE-2019-20386, CVE-2020-1712

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here